Data Processing Agreement — United Arab Emirates
The terms under which Cerrax processes your customers' personal data on your instructions.
This agreement forms part of the Terms of Service and applies whenever Cerrax processes personal data on your behalf. It uses the meanings given in Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL") — or, if your business is established in the DIFC or ADGM, in that free zone's data protection law (see section 16). Where this agreement and the Terms conflict on data protection, this agreement governs. It is governed by the same law as the Terms, and any dispute between us under it is resolved as section 17 of the Terms provides (arbitration under the LCIA Rules, seated in London); nothing in that affects the powers of the UAE Data Office or of a free zone's data protection authority.
1. Which of us is which
You are the controller of your customers’ personal data. We are your processor of it: we act on your instructions and use it for our own purposes only in the ways section 3 lists. That covers personal data about your customers, the people who enquire with you, your other contacts, and your staff and crew in their working role. For your own account data — your name, your login, your company’s settings and billing — we are a controller in our own right, and our Privacy Policy covers that.
One exception, which is your customer's choice, not yours. When your customer sends a video or photographs of their home, they may tick a separate box allowing Cerrax to keep them to train software that recognises furniture and rooms. For that use alone, Cerrax is a controller in its own right, on the customer's consent, and ourPrivacy Policy (§3) covers it: identifying details are blurred before it is ever used for training, nothing uses it today, and the customer can withdraw at any time, after which the video and photographs are deleted under the ordinary ninety-day rule. Everything else in this agreement applies to them as it does to the rest of your customers’ data.
2. What we process, and for how long
- Subject matter and purpose: running your moving company on Cerrax — receiving and organising your enquiries, keeping your customer records (contacts), pricing, quoting and following up quotes, booking and running jobs, and sending the messages you set up — on your instructions.
- What we do with it: collecting, storing, organising, reading (including with AI, to suggest details for a person at your company to confirm), pricing, sending messages on your behalf, de-identifying (section 9), exporting and deleting.
- Duration: for as long as your account is open, and afterwards only as section 8 allows.
- Type of personal data: names, addresses (building, community and emirate), contact details, move dates, and details of the property and its contents that you or your customer enter; where your crew use Cerrax on the day of the move, photographs of the property, its access and any damage found, together with the name and drawn signature of whoever signs the inventory off; and, where you invite it and your customer chooses to send one, a video of their home. Where you use them: your contacts (names, email addresses, phone numbers, company, preferred language, addresses used, the choices they gave you about your messages and when, where they came from, and your notes); enquiries, including the text of enquiry emails sent to your Cerrax lead address; the messages you send through Cerrax and whether they were delivered; follow-up tasks and their notes; whether a payment has been made (never card details); and reviews and ratings your customers give you.
- People it is about: people who enquire with you (whether or not they become customers); your customers; the people at the properties you move between; other people you keep as contacts; people named in notes, messages, photographs or video; and your staff and crew in their working role.
We do not ask for and do not want sensitive personal data. Please do not enter health, religious, biometric, criminal-record or similar information into free-text fields. If it arrives anyway — in an enquiry or a note — we hold it only as part of that record, never use it for pricing or learning, and keep it out of section 9.
A signature captured against an inventory is held as evidence that your customer agreed what was moved and in what condition. Nothing measures, compares or matches it, and it is never used to identify anyone — so we do not treat it as biometric data. Collecting signatures is optional: if you would rather your crew did not, simply do not use it.
3. We act on your instructions
We process your customers’ personal data only on your documented instructions — which include your use of the product and this agreement — and only for the purpose in section 2, unless the law requires otherwise, in which case we will tell you first unless the law forbids that. If we think an instruction breaks the PDPL, we will tell you promptly and may pause carrying it out until you confirm or change it. We keep a record of the processing we carry out for you.
Our own uses, and only these: the de-identification in section 9; keeping descriptions of a job's items and rooms, with any email address, phone number or address removed, for 30 days to improve how Cerrax recognises items (we keep no other text sent to our AI sub-processor); keeping the service secure and preventing abuse; and meeting our own legal obligations.
Your instructions include these, when you use the features concerned: receiving emails sent to your Cerrax lead address and reading them — using our AI sub-processor where an email has no labelled layout — to suggest details you confirm; keeping contact records and the choices your customers make about your messages; and sending the messages you switch on, in your name, identifying you and with your postal address, honouring every request to stop at once and for all of those messages from you to that person. We keep a record of each choice and each stop, and a scrambled record of a stop for as long as it must be honoured.
Also on your instructions, when you use the features concerned: sending your customers the messages about a job that you set up (by WhatsApp where you have connected it, otherwise by email), including a review request and the private rating and comment a customer may give you; creating links you choose to share — a job sheet for your crew, or evidence (the customer's name, photographs, video and signatures, never their contact details) for your insurer, broker or claims handler; publishing your jobs to calendar subscriptions you create; and keeping follow-up tasks and their notes.
4. Confidentiality
Everyone we allow to access your customers’ personal data is bound by a written duty of confidentiality that continues after they leave, and only sees what their role requires. Access inside the product is governed by roles and individual permissions, checked on the server for every request.
5. Security
We take the technical and organisational measures the PDPL requires to protect personal data against unauthorised access, loss, alteration or disclosure, described in our security overview — encryption in transit and at rest, role-based access control, an audit trail of consequential actions, point-in-time recovery and separate daily backups. That page states plainly what we do not yet have.
We will not materially reduce the overall level of security described there while this agreement lasts.
6. Sub-processors
You give us general written authorisation to use sub-processors. The current list is in section 8 of our Privacy Policy and is kept current there. We bind each of them by written contract to data protection obligations no less protective than these, and we remain fully responsible to you for their performance. We will email your account owner at least 30 days before a new sub-processor starts handling your customers’ personal data (sooner only in an emergency, such as a provider failing, and then we tell you as soon as we can). You may object within that time on reasonable data protection grounds; if we cannot resolve it, you may end the affected service or your subscription and we will refund any fees paid in advance for the unused period. Services you connect yourself under your own account with them — your own Stripe, WhatsApp Business or Xero account — act on your instruction under your agreement with them, and are not our sub-processors.
If you subscribe your own calendar to your Cerrax calendar link, your calendar provider fetches your jobs under your own agreement with it; it is not our sub-processor.
7. Helping you meet your own obligations
Taking into account the nature of the processing, we will help you with requests from the people the data is about — information and access, correction, erasure, portability, restriction and objection — and with your own duties on security, breach notification and impact assessments. If someone contacts us directly about data we hold for you, we will refer them to you rather than answer for you. If we become aware of a breach affecting your customers’ personal data, we will tell you without undue delay, and in any event within 48 hours, with the information you need to notify the UAE Data Office and the people affected as the PDPL requires.
You can find, export, correct and delete a contact or a job yourself in the product; for anything the product cannot do, we will act within 10 working days of your written instruction.
8. Deletion and return
Your instruction on how long we keep it. Unless you tell us otherwise, you instruct us to keep each job record — the quote, its booking and outcome, the crew's sheets and the photographs attached to them — for six years after the move (or after the quote, if the job did not go ahead), or for longer while a claim or dispute about that job is open, and then to delete it. A video, and any photographs your customer sends with it, are deleted 90 days after the job's last date unless your customer has separately agreed to their longer use. You can change this instruction by telling us.
At the end of the agreement you can export your data for 30 days. We then delete your customers’ personal data within 90 days, and it leaves our backups as they expire (within 98 days), except where the law requires us to keep it or you ask us to keep specific records, such as evidence in an open claim. Committed pricing records are never silently altered — personal identifiers within them are removed, which is how deletion is honoured without falsifying a record of what was quoted. Section 9 records are not your customers’ personal data and are not affected.
Unless you tell us otherwise, you also instruct us to delete: an enquiry that was never priced or sent, 12 months after its last activity; a quote that was sent but never accepted, 24 months after it was sent; and a contact record 12 months after the last job record linked to it is deleted (or 12 months after it was made, if it was never linked to a job). A record of a person's consent is kept while their contact record is kept and for six years after; a scrambled record of a request to stop messages is kept for as long as it must be honoured.
Two records keep their own periods: email delivery records (recipient, subject and whether it was delivered), 90 days; and the audit trail of actions in your account, up to six years after your account closes, with a customer's details removed when that customer is erased.
9. De-identified job data
(a) You instruct us to make de-identified records from the jobs we hold for you. (b) A de-identified record holds only the shape and economics of a job — volume, a distance band, access features, crew, vans, hours, price and cost, whether the quote was won and why not, the month of the move, and an area no finer than the first two letters of an area's name — and never a name, contact detail, full address or address, map position, free text, photograph, video, signature, your company's identity, or any reference that links it back to the job. (c) We treat a record as de-identified only when no one could reasonably identify a person from it, taking account of other information we or you hold. Data that can be linked back — for example by a job reference, or while we still hold the original job — is not de-identified and stays under this agreement until the original is deleted. (d) We will not try to re-identify anyone from these records, and require anyone we share them with to make the same commitment. (e) Once a record meets this standard it is not your customers’ personal data; it is ours, and we may keep and use it to improve and provide Cerrax, including after the underlying records are deleted and after this agreement ends. (f) We never show another company, or anyone else, your individual prices or anything that identifies your company.
10. Learning across firms
We use de-identified records under section 9, and statistics made from them, from across all firms using Cerrax, in every country, to improve the pricing engine for everyone, including you. This is stated here rather than assumed, because it is how the product gets better and we would rather you knew than found out.
11. Your numbers stay yours
Your rates, your margins, your customers and your prices are never visible to another firm, and never shown to the people you are quoting. The learning in section 10 runs on aggregated, de-identified signal — not on access to any one firm’s data by anybody else.
12. Audit
We will make available the information you reasonably need to show we are meeting these obligations — first by written answers and our security documentation — and will allow and contribute to a reasonable assessment by you or an independent assessor you appoint where those are not enough or a regulator requires it: at your cost, on 30 days' notice, under confidentiality, without access to other companies' data, and no more than once a year unless a regulator or a breach requires otherwise.
13. International transfers
We hold your customers’ personal data in the United Kingdom, in London, and you authorise that. It is a transfer out of the United Arab Emirates, made under Articles 22 and 23 of the PDPL: the United Kingdom has data protection legislation giving comparable protection, and by this agreement we are bound by contract to protect the data to the PDPL’s standard wherever we hold it. Where a sub-processor processes data outside the UK — the AI provider in the United States is the main case today — we bind it by contract to protection no less than this agreement’s. Where your data is stored on any given day is a question you can ask us at any time, and we will answer it for the day you ask.
Liability. Section 11 of the Terms of Service (limitation of liability) applies to this agreement.
14. Contact
Data protection questions, requests from the people the data is about, and breach notifications: hello@cerrax.io.
15. The PDPL’s processor terms, in one place
For your own records, this agreement gives you the commitments the PDPL expects of a processor: processing only on your instructions and for the agreed purpose and duration (sections 2 and 3); a record of processing (section 3); confidentiality (section 4); appropriate security measures (section 5); sub-processors bound by written contract (section 6); help with requests and breach notification (section 7); deletion or return at the end (section 8); information and audits to show compliance (section 12); and a lawful basis for cross-border transfer (section 13). If the PDPL or its Executive Regulations require a term this agreement does not contain, that term is treated as included, to the extent the law requires it.
16. If your business is in the DIFC or ADGM
If your business is established in the Dubai International Financial Centre, this agreement is the written processor contract required by the DIFC Data Protection Law (DIFC Law No. 5 of 2020); if it is established in Abu Dhabi Global Market, it is the written processor contract required by the ADGM Data Protection Regulations 2021. References to the PDPL and the UAE Data Office are then to be read as references to that law and to the DIFC Commissioner of Data Protection or the ADGM Office of Data Protection, and any term that law requires of a processor contract and this agreement does not contain is treated as included, to the extent the law requires it.